25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

White House Reviewing OSHA’s Proposed Rule on Infectious Diseases
Nov19

White House Reviewing OSHA’s Proposed Rule on Infectious Diseases

The White House Office of Information and Regulatory Affairs is conducting a final review of an Occupational Safety and Health Administration (OSHA) proposed rule that seeks to introduce new standards to better protect workers from infectious disease hazards such as COVID-19, SARS, tuberculosis, measles, varicella disease, and MRSA. The new standards will apply to healthcare and other occupational settings where employees face an increased risk of exposure to infectious diseases including nursing homes, homeless shelters, drug treatment programs, correctional facilities, coroners’ offices, mortuaries, emergency response facilities, and laboratories that handle materials that may be a source of pathogens. The new rule has been a long time coming. OSHA issued its initial Request for Information in May 2010, analyzed comments the same year, and held stakeholder meetings in July 2011, then the proposed rule stalled until 2014 when SBREFA was initiated and completed. OSHA has been examining regulatory alternatives for control measures to protect workers against infections disease...

Read More
Texas Hospitals Must Ask Patients About Their Citizenship Status
Nov19

Texas Hospitals Must Ask Patients About Their Citizenship Status

In August, Texas Governor Greg Abbott issued an Executive Order (GA-46) directing the Texas Health and Human Services Commission (HHSC) to start collecting information on patients who are not lawfully present in the United States and assess costs to the Texas public hospital system. “Texas will hold the Biden-Harris Administration accountable for the consequences of their open border policies, and we will fight to ensure that they pay back Texas for their costly and dangerous policies,” said Governor Abbott. The Executive Order took effect on November 1, 2024. While the Executive Order specifically mentions public hospitals, most private hospitals in Texas must also comply with this new requirement. The Executive Order states that hospitals covered by the executive order include acute care hospitals enrolled in Medicaid or the Children’s Health Insurance Program (CHIP), and the order also applies to other healthcare providers identified by the Health and Human Services Commission. Any hospital that fails to comply with the Executive Order could potentially be expelled from the...

Read More
Almost 39,000 Patients Affected by Email Breach at Oklahoma Spine Hospital
Nov19

Almost 39,000 Patients Affected by Email Breach at Oklahoma Spine Hospital

Unauthorized email account access has been detected by Oklahoma Spine Hospital, Familylinks, and the Massachusetts Department of Developmental Services and an emailing error by a Missouri Department of Mental Health employee resulted in the impermissible disclosure of patient data. Oklahoma Spine Hospital Oklahoma Spine Hospital in Oklahoma City has warned 38,945 patients about the exposure of some of their protected health information. Suspicious activity was identified in an employee’s email account on or around July 1, 2024. Immediate action was taken to secure its email tenant, and an investigation was launched to determine the nature and scope of the breach. The forensic investigation confirmed on September 24, 2024, that patients’ protected health information was stored in the compromised accounts including first and last names, dates of birth, financial account numbers and routing numbers, health insurance information, medical information, payment card information, and driver’s license information. At the time of issuing notifications, Oklahoma Spine Hospital was unaware of...

Read More
TriHealth Physician Partners Confirms Patient Data Exposed in Cyberattack
Nov18

TriHealth Physician Partners Confirms Patient Data Exposed in Cyberattack

Cyberattacks have recently been announced by TriHealth Physician Partners in Ohio and Harmac Medical Products in New York, and an insider breach has been discovered by North Texas Medical Specialists. TriHealth Physician Partners TriHealth, dba TriHealth Physician Partners (TriHealth), a primary care provider serving the greater Cincinnati area of Ohio, has warned patients about a security incident at one of its business associates that involved unauthorized access to patients’ protected health information. TriHealth said it learned about the incident at its vendor on October 23, 2024, and confirmed that there was no unauthorized access to its own network. The forensic investigation confirmed the attacker only had access to historical documents related to care provided by the OB/GYN group, For Women, prior to January 2020 when For Women joined TriHealth. An analysis of the affected files confirmed they contained names, addresses, dates of birth, Social Security numbers, claims information, medical conditions, medications, lab results, and other treatment information. TriHealth is...

Read More
Great Plains Regional Medical Center: 133,000 Patients Affected by Ransomware Attack
Nov18

Great Plains Regional Medical Center: 133,000 Patients Affected by Ransomware Attack

Great Plains Regional Medical Center in Elk City, OK, has fallen victim to a ransomware attack. The attack was detected on September 8, 2024, when files were encrypted. A third-party cybersecurity firm was engaged to assist with the investigation and determined that access was gained to its network on September 5, 2024, and continued until the incident was detected on September 8. Prior to encrypting files, the threat actor exfiltrated data from its systems that included names, demographic information, health insurance information, driver’s license numbers, clinical treatment information such as diagnosis and medication information, and Social Security numbers. Great Plains Regional Medical Center said it was able to quickly restore access to its systems, return to normal operations, and recover most of the encrypted data; however, a limited amount of patient data could not be recovered. Great Plains Regional Medical Center did not disclose the name of the ransomware group. The ransomware attack has recently been reported to the HHS’ Office for Civil Rights as involving the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist